Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law enters into force.
EU Whistleblower Protection Directive
Every private company with 50 or more employees operating in the EU must establish a confidential internal reporting channel, acknowledge reports within seven days, investigate and respond within three months, and protect reporters from all forms of retaliation. Non-compliance penalties reach up to €1M in some member states.
Next deadline:
The obligation is already in force. For companies with 250 or more employees in the EU, the compliance deadline was December 17, 2021. For those with 50 to 249 employees, it was December 17, 2023. Both deadlines have passed. The European Commission's July 2024 implementation report found widespread compliance gaps across member states. Organizations without a compliant internal reporting channel in place are currently in breach of national whistleblower protection law.
National implementing legislation differs in scope and enforcement approach: companies operating across multiple EU member states may face distinct obligations under each country's law, not just the Directive baseline. A group-level channel is not automatically sufficient for all jurisdictions.
Regulation timeline
What the EU Whistleblower Protection Directive requires
The EU Whistleblower Protection Directive (Directive EU 2019/1937) entered into force on December 16, 2019, setting minimum standards across all EU member states for the protection of persons who report breaches of EU law.
Private companies with 50 or more employees and all public sector entities, regardless of size, must establish a secure internal reporting channel, designate a responsible person to handle reports, acknowledge receipt within seven days, and provide substantive feedback on the outcome of the investigation within three months. Reporters must be protected from any form of retaliation, including dismissal, demotion, and blacklisting.
Covered breaches span public procurement, financial services, anti-money laundering, consumer protection, environmental protection, food safety, transport safety, public health, and data privacy. Each member state has transposed the Directive into national law, with the option to set stricter requirements than the Directive baseline.
Common whistleblower compliance challenges
General-purpose tools cannot meet the Directive's technical channel requirements
Internal reporting channel requirements go beyond a shared email address or a general HR portal: a compliant channel must protect reporter identity, support written and oral reporting, accommodate anonymous submission where national law requires it, and provide a two-way communication mechanism. General-purpose communication tools typically lack the access controls and anonymity architecture these obligations require.
Every report carries its own seven-day and three-month deadline
The seven-day acknowledgement and three-month feedback obligations apply to every individual report, not as an average response rate. A single missed deadline creates a documented compliance failure, and manual tracking is unreliable when report volumes increase or cases span multiple jurisdictions.
Member states have transposed the Directive with significant variation in scope and timelines
Germany's Whistleblower Protection Act (HinSchG), France's Law on Improving the Protection of Whistleblowers (Loi Waserman), and Spain's Law 2/2023 on the Protection of Persons Who Report Breaches of Law each add requirements beyond the Directive baseline. For companies operating across multiple EU member states, compliance means meeting the specific requirements of each national law, not just the Directive minimum.
GDPR obligations apply to every whistleblower report alongside Directive requirements
Whistleblower reports contain sensitive personal data about the reporter and, typically, about one or more individuals named in the report. GDPR requires a documented legal basis for processing, strict access controls on reporter identities, and a defined data retention policy that shared mailboxes and general HR systems cannot satisfy.
Compliant reporting channels and case management for EU and national whistleblowing law
Accept anonymous, pseudonymous, and identified reports through one configurable multi-channel intake
The osapiens HUB for Complaint Management accepts reports through a public reporting page, an AI-assisted chatbot, and email, available in more than 40 languages with voice recording and text-to-speech support for reporters who cannot read or write fluently. Anonymous reporters track case status through an encrypted complaint code that keeps their identity separate from the internal case ID, and the same channel covers complaint management obligations under CSDDD and LkSG.
Automatically route every report to the designated handler and track it against regulatory deadlines
Every report is automatically analyzed by integrated AI for risk category, affected countries, and named business partners, then assigned to the designated handler and tracked against the seven-day and three-month regulatory deadlines. Escalation alerts notify the compliance team before any deadline expires, and the complete audit trail is available in the Reporting Cockpit for CSRD disclosure under the relevant ESRS social indicators without a separate data export.
Enforce role-based access controls and produce structured case records for regulatory review
Role-based access controls restrict reporter identity visibility to the designated handler, and configurable data retention policies align with GDPR storage limitation requirements. Every case produces a structured record exportable as CSV for regulatory review, with the same documentation available in the osapiens HUB for Disclosure Management for combined financial and sustainability reporting.
Frequently asked questions
Directive (EU) 2019/1937 applies to all private companies with 50 or more employees operating in any EU member state, regardless of where the company is headquartered. Non-EU parent companies with EU subsidiaries or branches that exceed the employee threshold are also in scope. All public sector entities are covered regardless of size, and organizations in regulated sectors such as financial services, transport safety, and food safety may face additional obligations regardless of employee count.
An internal reporting channel must allow both written and oral reports, protect the confidentiality of the reporter's identity at all stages of the process, and provide a two-way communication mechanism so that reports can be acknowledged and followed up. Where national law requires it, the channel must also accept anonymous reports.
Organizations must designate a specific person or team to handle incoming reports; a shared general-purpose email address does not meet the confidentiality or access-control requirements set out in the Directive. Every report must be acknowledged within seven days, and the reporter must receive substantive feedback on the action taken within three months of filing.
Penalties are set by each member state and vary significantly.
The German Hinweisgeberschutzgesetz (HinSchG) provides fines of up to €20,000 for failure to establish a reporting channel and up to €50,000 for retaliation against a reporter.
The Spanish Law 2/2023 on the Protection of Persons Who Report Breaches of Law sets administrative sanctions for legal entities ranging from €100,000 up to €1,000,000 for breaches relating to the reporting channel, with the highest band reserved for failing to establish an internal reporting system at all; serious violations can additionally carry a public warning and a temporary ban on subsidies, tax benefits, or public-sector contracting.
The Polish Whistleblower Protection Act treats obstruction of a report, retaliation, and disclosure of a reporter's identity as criminal offences punishable by fine, restriction of liberty, or imprisonment.
Across all member states, organizations also face civil liability if reporters bring retaliation claims and may be subject to regulatory investigation in the event of a publicly disclosed compliance failure.
The EU Corporate Sustainability Due Diligence Directive (CSDDD) and Germany's Lieferkettensorgfaltspflichtengesetz (LkSG, German Supply Chain Due Diligence Act) each require in-scope companies to operate a grievance mechanism, but one with a wider reach than the Whistleblowing Directive.
The Whistleblowing Directive requires an internal, work-related reporting channel for employees and others in a work-related context, whereas CSDDD and LkSG require a publicly accessible channel open to any affected person, including supply-chain workers and external parties such as NGOs and trade unions. The underlying technical requirements nonetheless overlap substantially: confidential intake, structured case management, documented follow-up, and protection from retaliation.
The osapiens HUB for Complaint Management covers both: a publicly accessible complaint page, open to employees, supply-chain workers, and external parties, with anonymous or confidential submission, backed by the same structured case management and audit documentation each regime requires. Organizations meet the work-related channel of the Whistleblowing Directive and the public mechanism of CSDDD and LkSG through one system, rather than separate reporting channels for each regulation.
Yes. Directive (EU) 2019/1937 sets minimum standards, and member states were permitted to exceed them during transposition. Germany, France, and Spain have each added requirements that go beyond the Directive baseline, covering additional reporting categories, wider categories of protected persons, or shorter investigation timelines.
For companies operating across multiple EU member states, compliance means meeting the specific requirements of each national implementing law. The variations affect which types of breaches are reportable, which persons qualify for protection, and what penalties apply, making jurisdiction-specific configuration a practical necessity for international organizations.
Whistleblower reports contain personal data about the reporter and typically name one or more individuals as subjects of the report.
GDPR applies in parallel with the Directive: organizations must have a documented legal basis for processing report-related personal data, implement strict access controls so that only designated persons can view reporter identities, and define a data retention policy that satisfies storage limitation requirements.
A reporting channel that satisfies GDPR but fails the anonymity or two-way communication requirements set out in the Directive remains non-compliant, and vice versa. Both sets of obligations must be met by the same technical system.
The osapiens HUB for Complaint Management covers secure channel setup, structured case management, and automated deadline tracking on one platform. Compliance data connects directly to CSDDD due diligence management, LkSG grievance mechanism requirements, and CSRD disclosure workflows, with case records surfaced in the Reporting Cockpit for CSRD reporting and in the Disclosure Management module for combined financial and sustainability disclosure without a second collection exercise. Organizations managing multiple regulatory obligations avoid duplicate intake systems and manual data transfer between tools.